Skip to content

Latest commit

 

History

7 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

vulnImageProcessor

Basic Code Injection Vulnerable Image Processor developed to get experience on how rce work's via image uploading.

uponrunn

After running code.py you will get flag.txt and uploads in terminal .. But remember our AIM .

Goal is to Get Flag after uploading payload Embedded Image and running whoami after connecting from nc

Use RTLO to Triagger RCE and Keep Checking Metadata :)

Things to Consider

1.You have to upload your image inside upload directory, then enter the name of image after running code .

2.As this is focused on using RTLO , so embed payload with rtlo method used .

  1. use nc localhost port to connect .

  2. only run whoami to get flag.

WEB Version Coming Soon

About

Code Injection Vulnerable Image Processor

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages